Author Topic: Infected web site false positive?  (Read 2898 times)

0 Members and 1 Guest are viewing this topic.

jzig

  • Guest
Infected web site false positive?
« on: February 10, 2012, 10:40:07 PM »
Going to the following web site is blocked by Avast.  Avast says it is infected with js:Downloader-AZF [Trj]

 hxxp://www.roundrobininn.com/

Can anyone tell me if this is a false positive, or is it really infected.  I have a friend who sent me this website.  He doesn't use Avast and his AV software didn't flag anything.  Has he become infected?

Thanks.

Alievitan

  • Guest

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Infected web site false positive?
« Reply #2 on: February 10, 2012, 10:50:37 PM »
Site is infected and has a suspicious inline script, see: http://www.UnmaskParasites.com/security-report/?page=www.roundrobininn.com
See: http://vscan.urlvoid.com/analysis/18b641c6f27c9a30e1bac22eb7680f6d/aW5kZXg=/
It is the so-called JS/Agent nightmare hack you have fallen prey to - you will find script id="dgllhguk" in the script line, that avast flags as
JS:Downloader-AZF [Trj],

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Infected web site false positive?
« Reply #3 on: February 11, 2012, 12:02:30 AM »
Can anyone tell me if this is a false positive, or is it really infected.

It's really infected..!!!
http://sitecheck.sucuri.net/results/www.roundrobininn.com
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

cheapweb

  • Guest
Re: Infected web site false positive?
« Reply #4 on: February 15, 2012, 09:54:05 AM »
It has got to be something with the Avast program that is not right.

I scanned a site of mine which is constantly being blocked by the webshield, and i tried scanning it with both online url scanners suggested in this thread.

And surprise, THEY BOTH CAME UP CLEAN for my website.

Something needs to be done about this.

alenka

  • Guest
Re: Infected web site false positive?
« Reply #5 on: February 15, 2012, 11:08:12 AM »
Hello,

this is not a false positive. I see javascript code injected in the bottom of the site. The script starts with "<SCRIPT id="googleblogcontainer">var nf902ae4="";var e1060178120b5={". Looks like your site has been hacked. Once you clean it, avast will stop detecting it...

mortimernova

  • Guest
Re: Infected web site false positive?
« Reply #6 on: March 07, 2012, 08:01:43 PM »
it has been resolved and the malware script has been removed.